Vulnerabilities / Threats

6/29/2017
06:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Kaspersky Lab Faces More U.S. Scrutiny Over Potential Russian Govt. Influence

Lawmaker proposes ban on DoD use of Moscow-based security vendor's products.

Moscow-based Kaspersky Lab this week found itself the subject of escalating concerns about the company's possible connections with the Russian government.

The immediate worries this time were prompted by news that FBI agents had questioned several of the security vendor's US-based employees at or near their residences Tuesday night.

The employees were apparently informed they were not the subjects of any formal criminal investigation and that they were being interviewed as part of an effort to get general information about the company's operations and communications with Moscow.

It is unclear at this time if the questioning had anything to do with Special Counsel Robert Mueller's broader investigation into potential Russian interference in the U.S. elections last year.

News of the FBI's apparent investigation of Kaspersky's activities prompted U.S. Senator Jeanne Shaheen [D-NH] to propose a total ban on the Pentagon's use of Kaspersky's products. In an amendment Wednesday to a Senate Armed Services Committee defense spending policy bill, Shaheen said the prohibition was required because of reports that Kaspersky Lab "might be vulnerable to Russian government interference."

A Kaspersky Lab spokeswoman said neither the company nor its founder and CEO Eugene Kaspersky had any ties to any government. "The company has never helped, nor will help, any government in the world with any cyber espionage efforts," the spokeswoman said in a statement to Dark Reading.

Kaspersky Lab has been an IT security vendor for 20 years and has adhered to ethical practices. "Kaspersky Lab believes it is completely unacceptable that the company is being unjustly accused without any hard evidence to back up these false allegations," the statement said.

John Pescatore, director of emerging security threats at the SANS Institute and a former NSA analyst says that so far at least there indeed doesn't appear to be any credible evidence that Kaspersky Lab's products have been compromised or contain hidden doors. "NSA and the UK GCHQ have had many years to look at Kaspersky’s products and I've seen no warnings before this," Pescatore says.

At the same time though, there's little doubt that Russian intelligence agencies are just as interested as the NSA in exploiting cyber techniques to infiltrate other countries.

"NSA knew of vulnerabilities in US security products and told no one. Russia may have known of similar vulnerabilities in Kaspersky's products and told no one," he says.

Just as the NSA might have influenced U.S. technology vendors to leave vulnerabilities in their products, the Russian government could have done the same with Kaspersky. "Russia went further, in economic espionage and trying to influence our presidential election, but there are many other similarities."

The takeaway for organizations is that all software needs to be checked for vulnerabilities and malicious capabilities, he said.

This week's developments add to the pressure that the $620 million Kaspersky Lab has been under in recent years about possible links with the Russian government and intelligence agencies. The company's products are relatively widely used in the US by consumers, commercial entities, and government organizations.

In May, U.S. intelligence officials said they were investigating the government's use of Kaspersky Lab products and whether those products could be used to attack American systems. At a U.S. Senate Select Committee on Intelligence hearing on Russian interference, the U.S. director of national intelligence and other intelligence officials unanimously expressed discomfort about US Kaspersky Lab products on their computers without explaining why. That time, as now, Kaspersky denied the company had any links with the Russian government and suggested it was being picked on for political reasons.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Related content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Are you sure this is how we get our data into the cloud?
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17437
PUBLISHED: 2018-09-24
Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
CVE-2018-17438
PUBLISHED: 2018-09-24
A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
CVE-2018-17439
PUBLISHED: 2018-09-24
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.
CVE-2018-17432
PUBLISHED: 2018-09-24
A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.
CVE-2018-17433
PUBLISHED: 2018-09-24
A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.